Re: [Txauth] alternative charter writeup

Dick Hardt <dick.hardt@gmail.com> Thu, 16 January 2020 22:31 UTC

Return-Path: <dick.hardt@gmail.com>
X-Original-To: txauth@ietfa.amsl.com
Delivered-To: txauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BC921200B1 for <txauth@ietfa.amsl.com>; Thu, 16 Jan 2020 14:31:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.44
X-Spam-Level:
X-Spam-Status: No, score=-0.44 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_FONT_LOW_CONTRAST=0.001, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o0CXvLYQp179 for <txauth@ietfa.amsl.com>; Thu, 16 Jan 2020 14:31:31 -0800 (PST)
Received: from mail-lj1-x235.google.com (mail-lj1-x235.google.com [IPv6:2a00:1450:4864:20::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C0A7C12004A for <txauth@ietf.org>; Thu, 16 Jan 2020 14:31:30 -0800 (PST)
Received: by mail-lj1-x235.google.com with SMTP id w1so24390299ljh.5 for <txauth@ietf.org>; Thu, 16 Jan 2020 14:31:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=w1Ie5ec/pgdjc73ypo6verTvYqz0KJ8/8qhV3+Ea5zI=; b=r90zi76GsqEwSoNaMWW+HhZ4eqiWNBUxHWeM6MLFwLh272dktyb9MGgAl3chEdtMPu lgld9/BI/jkOHfANoeuGMKxGkqsdMnqjRq4+K+O3YLw1E0T7Aqcx0TtUTnr1ivV0NxLz K6aRpvHSQPG0TGGt/MR9DHV6eZMxmdO12CpfDod9ZeFySPlosq/F1jvBMIrcgVPAFf+A zkGIrCTutvL7nqjNXdjjwcKTppraCWyVPKpSfr3GE94IhpW8jSJELZtfOhJWtFFypK1Q nGeAlLM0G8xtufP0tnLm49yUCRxrVhLd76u7kJtyTrmxDc5wYUrIMo34hNZn4r0RtD45 nsCw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=w1Ie5ec/pgdjc73ypo6verTvYqz0KJ8/8qhV3+Ea5zI=; b=o/tuBVYm8G4P/1PGKkgTEljyRpK1tTtlbeHxHXcSuGrTWtiZvnmSgLKiC2J56DjKpz jm3lvsBdLzIUUpJueeyFvlIqte3z6XBcP6SlhqARg/w5mewc2Y2a+xeg+yE0TCBiicuK UJrI4Spo/c2cdmupQyJ29k1C9CwHtIuKFeM78+vkaq/NbBHtwQDwHj/xamHxZ6FoyEmC o7h+pWNAGISnlZTs6gWkJN1UQubgMtl+6ucWrNWwFH1977grJypCe5gMUZkA0flN+RTE nlM3ewH9L9pmJ9DUJ9A5bRs68jdrB/lNA+0oiBLKF3i0GNGWWn1FlYg+YLekoB2GeirG 5v2Q==
X-Gm-Message-State: APjAAAV/+W9EwE2SUKzqV6pN0tR+O6EYHzMmy4VYLXa/bDy3uzLcHFF1 SEL2FnHvXE7bwO8azli9piOznkdbo4IT7oDBHFw=
X-Google-Smtp-Source: APXvYqxDpdAMSGhQZbfLCqB5ZygV5giwgQ5SYOE9Qv44fdgDBGle7GRwOShEf9FlcB9TZTXyOngDmZF1CZv9NzZlwA8=
X-Received: by 2002:a2e:7505:: with SMTP id q5mr3742212ljc.7.1579213888817; Thu, 16 Jan 2020 14:31:28 -0800 (PST)
MIME-Version: 1.0
References: <857A822F-E819-443E-8D92-5A5BD682D3AF@mit.edu> <3CC78FFE-8115-4693-8FEF-EC9B9BDDD786@lodderstedt.net>
In-Reply-To: <3CC78FFE-8115-4693-8FEF-EC9B9BDDD786@lodderstedt.net>
From: Dick Hardt <dick.hardt@gmail.com>
Date: Thu, 16 Jan 2020 14:31:17 -0800
Message-ID: <CAD9ie-vcV1LRr+nd8MPFtzMyEdPPJFy3r3PcV15kSu2W3NJLcg@mail.gmail.com>
To: Torsten Lodderstedt <torsten@lodderstedt.net>
Cc: Justin Richer <jricher@mit.edu>, "txauth@ietf.org" <txauth@ietf.org>, "rdd@cert.org" <rdd@cert.org>, "Richard Backman, Annabelle" <richanna@amazon.com>, Benjamin Kaduk <kaduk@mit.edu>
Content-Type: multipart/alternative; boundary="000000000000de1ade059c4962d7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/pT31kwF-YW1gSeY87Bk_K0c2AaI>
Subject: Re: [Txauth] alternative charter writeup
X-BeenThere: txauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <txauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/txauth>, <mailto:txauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/txauth/>
List-Post: <mailto:txauth@ietf.org>
List-Help: <mailto:txauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/txauth>, <mailto:txauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Jan 2020 22:31:32 -0000

I think of the resource as a container that has certain capabilities. An
early use case for delegation was for access to Flickr photos. Write access
to upload new photos was a capability.

An example of a resource without an API is where the client is also the
resource, and has delegated authorization to the AS. For example, you can
imagine a photo copier where you scan a QR code that send you to an AS that
then returns an artifact to the client how the user is authorized to use
the photo copier.
ᐧ

On Thu, Jan 16, 2020 at 8:15 AM Torsten Lodderstedt <torsten@lodderstedt.net>
wrote:

>
>
> > Am 16.01.2020 um 16:45 schrieb Justin Richer <jricher@mit.edu>:
> >
> > - Approval of identity claims and multiple resources in a single
> interaction
>
> This sounds a bit incomplete to me. I assume the user would approve „the
> attestation of identity claims“. I furthermore think the user would approve
> „access to multiple APIs“. I would prefer API over resource because it is
> more universal. For example, the protocol could also be used to create
> resources.